← Back to context

Comment by SoftTalker

4 hours ago

A Jordanian teen is behind ShinyHunters? I don't know if this is impressive or just a sad commentary on the state of security at the organizations they ransomed.

Never underestimate the amount of free time a teenager has (both in doing things and teaching themselves), most might not be up to adult levels but many capable ones are far more capable than many adults doing their jobs.

I was offered my first outside job after the second year of highschool, I kinda accidentally interviewed for a at the time respected gamedev firm (since I was looking for a summerjob heh) and when we started talking about when to start and I mentioned my school semesters the interviewer realized that I was younger than he had assumed.

I seem to remember something similar, with Fluffi Bunni, a notoriously good *NIX hacker group.

I think it turned out to be mostly one guy, but he wasn't a teenager, anymore, when they finally got him[0]. I know that after that arrest, the group disappeared.

I think that some of the kids they are nailing for ShinyHunters actually ordered hits.

Maybe publicly going after the FBI wasn't such a bright move... They could have kept it quiet, and made millions, selling to bad guys.

[0] https://www.csoonline.com/article/510783/data-protection-flu...

The original group behind ShinyHunters went to prison and Rey took it over.

They're trolling him saying he's not nearly as good and tarnishing the ShinyHunters rep.

I have no idea what's true, but they can all go to hell.

I would be inclined to doubt it based on the history of the group. Its more likely he is just a fall guy

  • yeah otherwise why would their rules forbid targeting PRC/DPRK/Russia/Belarus companies but not Jordan...

Hard-to-reach targets probably become a lot easier to reach when you have years' worth of stolen credentials and private data.

I think more modern security is an "emperor has no clothes" situation than people think. The LLMs are gonna have a field day.

  • > I think more modern security is an "emperor has no clothes" situation than people think.

    Outside of a few cases, it's always been a box checking exercise. If you're fortunate, the boxes are kept up to date / written by somebody that knows what they're doing. If you're like most, the box hasn't changed since the 90s when "complex passwords, changed quarterly" was in vogue.

  • Companies always prioritize features/capabilities up until shit starts hitting the fan, but even then the culture and requirements makes everything just a job of trying to patch a sinking ship if you're lucky.